Event Defintion - Alert Trigger - check if message is true in the last 10 minutes

Hi everybody,

i am currently trying to build an alert, which will be triggered if a message has just existed and already existed 10 minutes ago.


message: “Test” -> true & message: “Test” (10 minutes ago) -> true ==> Trigger alert

Does anyone of you know a solution to this problem?

Thanks :slight_smile:

he @tobi60

that is what the correlation feature is given for.

Thanks for the quick answer.

I am currently using Graylog Open Source, so there is no way to use any workaround for this feature?

If you are ingesting less than 5G a day, you can apply for a free enterprise license.

